CVE-2014-0821

N/A Unknown
Published: February 27, 2014 Modified: April 29, 2026
View on NVD

Description

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 and CVE-2013-6931.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://cs.cybozu.co.jp/information/gr20140225up04.php
Source: vultures@jpcert.or.jp
Vendor Advisory
http://jvn.jp/en/jp/JVN71045461/index.html
Source: vultures@jpcert.or.jp
Vendor Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000024
Source: vultures@jpcert.or.jp
Vendor Advisory
http://www.securityfocus.com/bid/65809
Source: vultures@jpcert.or.jp
https://support.cybozu.com/ja-jp/article/7993
Source: vultures@jpcert.or.jp
Vendor Advisory
http://cs.cybozu.co.jp/information/gr20140225up04.php
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://jvn.jp/en/jp/JVN71045461/index.html
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000024
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/65809
Source: af854a3a-2127-422b-91ae-364da2661108
https://support.cybozu.com/ja-jp/article/7993
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

10 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.4%
60th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cybozu